Files
portal/docs/governance/decisions/shared-system-sso-credentials.md
T
jarvis-at-skic d1bb6f8b18
Build and publish Corp v1 Board portal / build (pull_request) Successful in 35s
docs: govern shared Corp v1 SSO login
2026-08-27 20:53:22 +00:00

2.8 KiB

title
title
Shared Corp v1 system SSO credentials

Shared Corp v1 system SSO credentials — 2026-08-27

Context

Hermes sometimes needs to authenticate to Corp v1 systems being built or operated in order to perform an explicitly authorized task. Asking project members to retransmit credentials through Discord or storing them in project artifacts would create avoidable exposure.

Decision

RootAtSkic (discord:1518725627845283888) approved use of the shared Bitwarden-injected Corp v1 SSO identity in Board message 1542636538305712199.

Skills and records may contain only these runtime secret names:

  • HL_V1_SSO_EMAIL
  • HL_V1_SSO_PASSWORD

Credential values, Bitwarden object identifiers, and account metadata must not be copied into Discord, skills, repositories, prompts, command lines, URLs, files, screenshots, logs, CI output, or reports.

Operating rules

  • SSO secret availability is a capability, not authorization. Every login must serve an explicitly authorized project task and verified destination origin.
  • Hermes checks only whether both runtime variables are present and uses them through a trusted login form or provider-supported secure runtime interface.
  • Missing injection is reported by secret name only; no local fallback secret is created and no human is asked to paste a value into chat.
  • Login does not authorize account recovery, MFA or credential changes, permission changes, billing, spending, destructive operations, or unrelated system/data access.
  • Reports contain only the target system, authorized purpose, login result, and non-sensitive verification evidence.

Implementation and verification

The central corp-v1--main skill was updated to version 4.4.0 and merged through PR 9 at b11b0e521dab6b7a920337feed37c5a849d507bd.

The same secret-safe login section was published central-first to all seven corp-v1-channel-* reference skills, then semantically adopted into all 21 project channel skills across AeroSim, Maze Next Gen, and E-Shop v1. Every project-local authorization override was hash-checked before and after adoption, project bindings and supporting files were preserved, and every pushed default ref and SKILL.md marker was read back. All 21 installed Hermes runtime packages were refreshed from the resulting project repositories. The exact repository, branch, commit, and override coverage is recorded in the shared SSO skill rollout ledger.

Runtime preflight confirmed both secret names are currently injected. No credential value was read into a report, persisted, or committed.

Consequences

Every Corp v1 channel now follows one login path and one non-disclosure policy. Authentication can support authorized delivery work without turning credential availability into broader system authority.